cbcvebase.
CVE-2022-50232
published 2025-06-18

CVE-2022-50232: In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue was fixed upstream by accident in…

PriorityP420medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.17%
6.9th percentile
In the Linux kernel, the following vulnerability has been resolved: arm64: set UXN on swapper page tables [ This issue was fixed upstream by accident in c3cee924bd85 ("arm64: head: cover entire kernel image in initial ID map") as part of a large refactoring of the arm64 boot flow. This simple fix is therefore preferred for -stable backporting ] On a system that implements FEAT_EPAN, read/write access to the idmap is denied because UXN is not set on the swapper PTEs. As a result, idmap_kpti_install_ng_mappings panics the kernel when accessing __idmap_kpti_flag. Fix it by setting UXN on these PTEs.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.16.7-1 (bookworm)linux 5.16.7-1 (bookworm)
linuxlinux
linuxlinux>= 18107f8a2df6bf1c6cac8d0713f757f866d5af51 < 775871d4be0d75e219cca937af843a4a1b60489a775871d4be0d75e219cca937af843a4a1b60489a
linuxlinux>= 18107f8a2df6bf1c6cac8d0713f757f866d5af51 < c3cee924bd855184d15bc4aa6088dcf8e2c1394cc3cee924bd855184d15bc4aa6088dcf8e2c1394c
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 0 < 5.16.7-15.16.7-1
linuxlinux_kernel>= 5.13 < 5.15.605.15.60
linuxlinux_kernel>= 5.16 < 6.06.0
msrcazl3_kernel_6.6.96.2-1_on_azure_linux_3.0
msrcazl3_kernel_6.6.96.2-2_on_azure_linux_3.0

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_msrc4.1MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.